ClawHub
ClawHub is the public skill registry and marketplace for OpenClaw, the self-hosted personal AI agent. Developers publish text-based `SKILL.md` bundles, browse by category and vector search, and install them into any OpenClaw instance with a single `clawhub install <slug>` command.
The openclaw/clawhub repo was created January 3, 2026 and clearFrame shipped publicly shortly after — skills grew from a few hundred to 52k+ tools and 180k users by mid-April 2026. Anyone with a week-old GitHub account can publish; Hermes Agent can also install skills from the registry, making it the de-facto agent-skill npm across competing runtimes.
npm for AI agent skills — a registry with versioning, vector search, and a one-line CLI install, feeding every major self-hosted agent runtime.
Search Interest
-
Nascent0–7 days
-
Emergent8–30 days
-
Validating31–90 days
-
Rising ← now91–180 days
-
Established180 days +
Why is it emerging now?
ClawHub crossed 52k skills and 180k users in under 16 weeks while surviving a February supply-chain attack that infected 341 skills (Koi Security / 1Password disclosure). An April 15 independent audit of 2,354 skills reset the security narrative — 4.4% malicious, 86% vulnerable — turning the registry from a feature into a category-defining piece of agent infrastructure.
Outlook
6-month signal projection and commercial timeline.
Registry network effects compound with OpenClaw's 359k stars; Hermes already installs ClawHub skills, cementing it as cross-runtime default.
Risk · If ClawHavoc-style supply chain attacks recur, enterprise adoption could stall and a curated fork could peel off the top tier.
Analogs · npm · Hugging Face Hub · VS Code Marketplace
-
nowFree registry, adjacent paid
Registry itself free; money flows to hosting, audits, skill-bundle courses, and commercial ClawHub mirrors.
-
3-6moPaid security + directories
Paid scanners and curated-skill directories emerge as ClawHavoc-style attacks sustain enterprise scanning demand.
-
6-12moManaged registry tier
Enterprise registry with signed skills, SBOMs, and compliance-ready mirrors becomes the monetization wedge.
Competition & Opportunity for term “ClawHub”
Three heuristic signals derived from the tracked queries, the term's monetization cards, and its cluster neighbors. Directional, not audited.
Ideas for term “ClawHub”
Buildable pitches — turn this term into an article, site, product, post, newsletter, video, or course. Steal any card and run with it.
52k skills, no first-party top-20 list; DataCamp and community blogs split the SERP. Evergreen ranking + CPC from OpenClaw-adjacent tools (hosting, audits).
Official docs explain CLI commands but no end-to-end publishing tutorial covers naming, versioning, and passing the week-old-account gate. High-intent query with growing volume.
After ClawHavoc and the 4.4% malicious rate, 'is this ClawHub skill safe' is a live worry. Walkthrough + checklist + links to Trent/Koi scanners answers the exact question.
Creators of reusable agent skills now have three target registries. No comparison of publishing economics, review policies, or install reach exists on page one.
trent.ai and claw-hub.net already hint at the gap. A site that runs continuous scans, publishes per-skill reports, and issues a trust badge rides the security narrative as a SEO and affiliate play.
Prompt-injection, credential-harvesting, and phantom-implementation patterns are well-documented. A `clawhub-audit <slug>` tool with a paid CI integration addresses enterprise concern directly.
Skill authors currently hand-copy metadata across registries. A one-shot publisher with consistent versioning saves hours and becomes the default author tool across runtimes.
First-person HN / dev.to piece. Publishing economics, review friction, install analytics, the ClawHavoc angle — all unreported from an author POV.
ClawHub went from an empty GitHub repo on January 3 to 52,000 skills and 180,000 users by April — npm took three years to hit that curve.
Trent AI audited 2,354 ClawHub skills. 103 were malicious, 86% vulnerable, and traditional scanners caught almost none. The surprising part: enterprises are leaning in harder, not pulling out.
Publishing to ClawHub takes a week-old GitHub account and one CLI command. Making that skill actually safe for a stranger's agent took me three days.
What People Search
Long-tail queries from Google Suggest + Trends. Volume and competition are heuristics — directional, not audited. Content Type comes from query shape.
SERP of term “ClawHub”
What searchers see today — organic results on top, paid ads if anyone's bidding. Ad density is a real-time commercial signal.
Related Terms
Other terms in the same space — aliases, subtypes, competitors, and neighbors to explore next.
- Part of OpenClaw OpenClaw is an open-source self-hosted personal AI agent: a long-running runtime that connects to any LLM (Claude, GPT, DeepSeek, Kimi,… →
- Related Hermes Agent Hermes Agent is an MIT-licensed, self-improving AI agent from Nous Research designed to live on a server — local, VPS, or serverless —… →
- Related Claude Code Claude Code is Anthropic's official command-line coding agent — a terminal tool that reads your codebase, edits files, runs commands,… →
- Related Agent Harness An agent harness is the middleware between a large language model and the real world — code that runs the agent loop, calls tools,… →
- Related Managed Agents Managed Agents is an infrastructure paradigm where cloud platforms host, orchestrate, and operate AI agents as a service. →
- Related MCP Server An MCP server is a small, standalone program that exposes one capability — a database, a filesystem, a security scanner, a trading API —… →
- Competitor HermesHub·VS Code Marketplace
- Related ClawHavoc·agentskills.io
Sources
Primary URLs this report cites — open any to verify the claim yourself.
- 01 ClawHub — official marketplace clawhub.ai ↗
- 02 openclaw/clawhub on GitHub github.com ↗
- 03 OpenClaw docs — ClawHub reference docs.openclaw.ai ↗
- 04 1Password — From Magic to Malware 1password.com ↗
- 05 Trent AI — 2,354 ClawHub Skills Analysed trent.ai ↗
- 06 The New Stack — Persistent AI Agents Compared thenewstack.io ↗
- 07 eSecurity Planet — Malicious Skills Found in ClawHub esecurityplanet.com ↗